Also known as: tracked as, UNC6619
CL‑STA‑1087 is widely believed to be a Chinese state‑sponsored advanced persistent threat that has been active since 2020. The campaign’s primary objective is espionage against defense, government, media, critical infrastructure, mining, financial services, telecommunications, utilities, energy, and aviation sectors in countries such as China, the United States, Brazil, India, Mexico, Germany, Vietnam, Taiwan, Belarus, Poland, Italy, South Korea, Saudi Arabia, Japan, and Nigeria. Operationally the actors demonstrate exceptional patience: once an intruder foothold is established they often remain dormant for months or years, leveraging legitimate cloud services as their C2 infrastructure to blend with normal traffic and evade detection. Their toolset is broad and includes known commercial tools such as PowerShell and Cobalt Strike variants, open‑source reconnaissance utilities (e.g., TruffleHog), specialized custom backdoors, and a range of credential harvesting techniques (Mimikatz and OAuth token theft). They have also been observed manipulating file extensions, icons, and embedded images or scripts to masquerade malicious executables as benign office documents. The group leverages social engineering (spearphishing emails with malicious attachments or links) in combination with purchased intelligence to create highly targeted lures that improve the likelihood of user execution.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CL‑STA‑1087 is a state‑sponsored espionage group originating from China that has operated since at least 2020, primarily targeting military and critical infrastructure entities in Southeast Asia. The gang employs sophisticated spearphishing campaigns with malicious attachments or links designed to exploit software vulnerabilities, gather credentials—including OAuth tokens—and establish persistent, often dormant, cloud‑based command‑and‑control channels. Recent evidence shows a continued focus on precision intelligence collection while maintaining strong operational security, making detection and attribution challenging for defenders.
Goals & Targeting
CL‑STA‑1087’s strategic objective is long‑term state‑level espionage focused on acquiring tactical and operational intelligence from military and critical‑infrastructure targets. By embedding dormant access and using cloud native C2, the group can persist undetected while collecting data such as system inventories, network configurations, credentials, and documents. The use of spearphishing tailored to specific organizations suggests a goal to gain footholds inside sensitive networks for targeted information gathering rather than opportunistic sabotage.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
40
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics